๐Ÿ” CVE Alert

CVE-2026-63266

UNKNOWN 0.0

Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.

CWE CWE-22
Vendor the document foundation
Product libreoffice
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for the document foundation libreoffice

Be the first to know when new unknown vulnerabilities affecting the document foundation libreoffice are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The Document Foundation / LibreOffice
26.2 < < 26.2.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
libreoffice.org: https://www.libreoffice.org/about-us/security/advisories/cve-2026-63266

Credits

๐Ÿ” Thomas Rinsma and Edoardo Geraci from Codean Labs Caolรกn McNamara of Collabora Productivity